[prev in list] [next in list] [prev in thread] [next in thread] 

List:       kde-core-devel
Subject:    Fwd: Bug#17202: unlocking screensaver with any password
From:       Daniel Naber <daniel.naber () t-online ! de>
Date:       2001-01-05 0:01:06
[Download RAW message or body]


Hi,

does someone have any idea how to fix this the right way? The way it was 
before you couldn't get rid of the lock, now there is no lock :-(

regards
 Daniel

----------  Forwarded Message  ----------
Subject: Re: Bug#17202: unlocking screensaver with any password
Date: Sun, 17 Dec 2000 00:31:46 +0000
From: David Faure <david@mandrakesoft.com>
To: daniel.naber@t-online.de


On Sunday 17 December 2000 00:12, you wrote:
> Package: kdesktop
> Version: cvs 2000-12-17
> Severity: critical
> Installed from: source
>
> Currently you can unlock your screensaver with any
> password, if kcheckpass is not installed suid root. I know
> that coolo changed it to be this way, because before you
> couldn't unlock it at all.
>
> Still I think this is a security problem, even if it only
> occurs with a "broken" installation. Perhaps we could just
> check for the suid bit before starting the saver? I
> already played around to find a cleaner solution, but I
> don't know one (and I won't play with the setuid programs).

The problem is, I'm the one getting the kdesktop bug reports
and I have no clue about this issue.

The maintainer for klock is Martin Jones <mjones@powerup.com.au>,
maybe you want to contact him ?
Or kcheckpass, Christian Esken <esken@kde.org>.
I'm guessing kde-core-devel would be a better place discussing this,
since there is more than one package involved.

--
David FAURE, david@mandrakesoft.com, faure@kde.org
http://www.mandrakesoft.com/~david/, http://www.konqueror.org/
KDE, Making The Future of Computing Available Today

-------------------------------------------------------

-- 
Daniel Naber, Paul-Gerhardt-Str. 2, 33332 Guetersloh, Germany
Tel. 05241-59371, Mobil 0170-4819674

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic